← Help

Guest hospitality

SMS senders and delivery recovery

Product documentation · Reviewed

SMS senders and delivery recovery

An owning workspace administrator can review guest texts, but only its current owner can bind or revoke the business’s SMS sender in Settings → SMS sender. Provider configuration alone does not enroll a workspace or send a text. The deployment configuration must assign that exact number and account to the workspace before it can be selected.

Review the sender

Review the business name, sending number and sender type. Confirm the choice using the current revision. Saving the same interrupted request returns its recorded result without creating another binding. The owner’s current permission is checked again after any database wait, including when recovering an earlier request.

A credential rotation can retain the account, number and business consent scope. Moving an already-used number to another account, brand, sender type or workspace is held for a separate governed migration. Merely changing a label must not erase a phone’s earlier opt-out or route its replies into another business.

This slice supports verified United States destinations. A number beginning with +1 is not sufficient: Canada and other North American Numbering Plan territories remain outside this policy. Reviewed toll-free senders use their applicable concatenated-message segment limit. Messages retain their exact GSM or Unicode segment quote, configured rate, price revision and maximum cost; existing deliveries are not repriced later. Paid and zero-price reservations both require an enabled usage account and an approved cap.

Understand delivery states

Each newly dispatched text freezes its exact account, sender, destination, message, callback identity and spending reservation. Its start marker commits before the provider call. Only that owning worker may make the one create request.

Accepted means the provider returned a matching message identity. Delivered requires verified delivery evidence. A later failure callback does not change a delivered receipt. A confirmed carrier opt-out blocks future messages to that exact sender and phone.

Uncertain means the provider may have accepted the text. Do not create another message to work around it. No automatic create retry is permitted, including after a crash between saving the start marker and beginning the network call. Its original spending reservation stays held until authoritative evidence arrives. A known provider message identity can be checked; the system never guesses a matching message from its phone, body or approximate time.

A callback may arrive before the original HTTP response. Matching callbacks settle the same reservation once. Credential changes cannot move an old attempt into a new provider account. Retained callbacks require the original, explicitly configured credential generation. Keep the original credential reference available for reconciliation until its outstanding attempts have been resolved.

STOP, START and private replies

Carrier STOP is recorded separately from wedding consent and is processed even when spending is paused. START alone does not enroll a household, clear an uncertain message or resume a queue. After START, the guest must review a fresh enrollment and prove the phone using the displayed one-time inbound code before newly reviewed texts become eligible. An intervening STOP invalidates that review.

An ordinary reply must have one current household context. Ambiguous replies remain private host review items; the service does not choose the latest wedding or copy the reply to every household. The exact reply code in a delivered invitation can select its intended household. SMS consent does not authorize email marketing, and an email preference does not authorize text messages.

Retained wedding-day messages

New wedding-day texts use this same frozen transport and require an explicitly reviewed workspace sender. Earlier attempts that lack a frozen account, sender and destination remain held. Current contact details cannot prove where a historical message was sent, so the old callback URL cannot silently invent that evidence or resend the message. Existing opted-in email fallback behavior remains separate.

Coordinated activation

The sender, consent, pricing, storage and callback workflows are exercised with disposable PostgreSQL databases and deterministic provider adapters. Live provider accounts, registered sending numbers, toll-free or application-to-person registration, approved messaging policies, inbound/status webhook configuration and delivery tests remain part of coordinated activation. No real SMS or provider configuration is performed by the local rehearsal. Carrier costs for inbound traffic require a separately reviewed accounting policy; this slice does not silently add them to a guest’s consent or the workspace’s outbound quote.